首页> 外文期刊>Journal of management information systems >Managing Interdependent Information Security Risks: Cyberinsurance, Managed Security Services, and Risk Pooling Arrangements
【24h】

Managing Interdependent Information Security Risks: Cyberinsurance, Managed Security Services, and Risk Pooling Arrangements

机译:管理相互依赖的信息安全风险:网络保险,托管安全服务和风险汇总安排

获取原文
获取原文并翻译 | 示例
           

摘要

The interdependency of information security risks often induces firms to invest inefficiently in information technology security management. Cyberinsurance has been proposed as a promising solution to help firms optimize security spending. However, cyberinsurance is ineffective in addressing the investment inefficiency caused by risk interdependency. In this paper, we examine two alternative risk management approaches: risk pooling arrangements (RPAs) and managed security services (MSSs). We show that firms can use an RPA as a complement to cyberinsurance to address the overinvestment issue caused by negative externalities of security investments; however, the adoption of an RPA is not incentive-compatible for firms when the security investments generate positive externalities. We then show that the MSS provider serving multiple firms can internalize the externalities of security investments and mitigate the security investment inefficiency. As a result of risk interdependency, collective outsourcing arises as an equilibrium only when the total number of firms is small.
机译:信息安全风险的相互依赖性通常会导致企业在信息技术安全管理中进行低效的投资。网络保险已被提议作为一种有前途的解决方案,以帮助公司优化安全支出。但是,网络保险无法有效解决因风险相互依赖而导致的投资效率低下的问题。在本文中,我们研究了两种替代的风险管理方法:风险汇总安排(RPA)和受管安全服务(MSS)。我们表明,公司可以使用RPA作为网络保险的补充,以解决由安全投资的负面外部性引起的过度投资问题;但是,当证券投资产生积极的外部性时,采用RPA对公司而言就不是激励兼容的。然后,我们证明为多个公司提供服务的MSS提供程序可以内部化安全投资的外部性并减轻安全投资的效率低下。由于风险相互依赖,只有在公司总数很小的情况下,集体外包才作为平衡出现。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号